Arista
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Arista product.
RSS Feeds for Arista security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Arista products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Arista Sorted by Most Security Vulnerabilities since 2018
Known Exploited Arista Vulnerabilities
The following Arista vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Arista VeloCloud Orchestrator Improper Input Validation Vulnerability |
Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. CVE-2026-93952 |
September 22, 2026 |
| Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability |
Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. CVE-2026-16812 Exploit Probability: 1.0% |
July 27, 2026 |
| Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability |
Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. CVE-2026-7473 Exploit Probability: 0.4% |
June 9, 2026 |
By the Year
In 2026 there have been 29 vulnerabilities in Arista with an average score of 5.7 out of ten. Last year, in 2025 Arista had 12 security vulnerabilities published. That is, 17 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 2.35
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 29 | 5.70 |
| 2025 | 12 | 8.05 |
| 2024 | 4 | 7.55 |
| 2023 | 5 | 7.48 |
| 2022 | 6 | 7.60 |
| 2021 | 4 | 6.50 |
| 2020 | 11 | 6.83 |
| 2019 | 5 | 6.50 |
| 2018 | 3 | 7.00 |
It may take a day or so for new Arista vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Arista Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-73462 | Sep 16, 2026 |
Arista EOS IGMP Snooping Crash CVE-2026-73462On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected VLAN to cause the IGMP snooping agent to terminate unexpectedly. This results in a temporary disruption of multicast traffic management, which may cause multicast traffic to be flooded to all ports of the affected VLAN until the service recovers. Repeated exploitation could result in a prolonged loss of intended multicast forwarding behavior. |
|
| CVE-2026-73457 | Sep 16, 2026 |
Clear-text gNPSI Client Credentials Logged on Arista EOSUnder certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, the gNPSI client credentials might be logged in clear text in local or remote accounting logs to authenticated users. |
|
| CVE-2026-73456 | Sep 16, 2026 |
Arista EOS gRPC gNPSI Remote Code Execution via Unauth ClientUnder certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch. |
|
| CVE-2026-73442 | Sep 16, 2026 |
Arista EOS VRRP Auth Credentials Logged in CleartextOn affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving forwarded log output) to obtain the peer device VRRP authentication credentials without having access to the network segment on which VRRP is running. |
|
| CVE-2026-77190 | Sep 16, 2026 |
Arista EOS PIMSM Agent DoS 4.34-4.36On affected platforms running Arista EOS, an unauthenticated attacker who is network-adjacent to the switch and able to connect to a device with PIM Sparse Mode and MLAG configured, can send malformed messages that cause the Pimsm agent to terminate unexpectedly. The Pimsm agent is automatically restarted, but repeated attacks can cause the agent to restart continuously, resulting in a sustained denial of service. |
|
| CVE-2026-73468 | Sep 16, 2026 |
Arista EOS Multicast Forwarding State Premature Expiry (<=4.36.1F)A specially crafted packet can cause the premature expiry of multicast forwarding state on affected interfaces, potentially resulting in temporary multicast traffic loss during the affected period. |
|
| CVE-2026-73440 | Sep 16, 2026 |
Arista EOS SNMPv3 Credential Exposure via Hashed Key in ConfigOn affected platforms running Arista EOS with Simple Network Management Protocol (SNMP) configured, SNMPv3 local or remote user credentials may be exposed as a one-way hashed, localized key value within the device's running and sanitized configurations. An authenticated user who gains access to this sensitive information could leverage it to perform unauthorized read operations on SNMP tables or to send fraudulent trap notifications to the Network Management System (NMS). This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks. |
|
| CVE-2026-73469 | Sep 16, 2026 |
Arista EOS 4.35.0F-4.35.4M Loose uRPF Lacks Drop on 7050X4/7358X4When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop. Consequently, traffic that should be dropped based on these routes could still be processed and forwarded by the device. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks. |
|
| CVE-2026-73453 | Sep 16, 2026 |
Arista EOS P4Runtime unauth RCE via crafted packet injectionAn unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime. P4Runtime is disabled by default in Arista EOS. By crafting a malicious packet during the initiation of a P4Runtime session, an attacker can obtain complete administrative control over the compromised switch. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks. |
|
| CVE-2026-73455 | Sep 16, 2026 |
Arista EOS OSPFv3 Agent Restart Vulnerability (Before 4.36.0.1F)On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can cause the OSPFv3 agent to restart unexpectedly. |
|
| CVE-2026-73438 | Sep 16, 2026 |
Arista EOS OSPFv3 Agent Restart via Unauth Packet CrashOn affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, an unauthenticated attacker on the same OSPFv3 broadcast domain can send a specially crafted set of packets that can cause the Ospf3 agent to restart unexpectedly. The crash results in the loss of all OSPFv3 adjacencies on the affected device and may disrupt routing across the broader OSPF domain until the agent recovers. This issue was reported externally by Dravanet Inc., and Arista is not aware of any malicious exploitation of this vulnerability in customer networks. |
|
| CVE-2026-73436 | Sep 16, 2026 |
Arista EOS OSPFv2 Packet Causing OSPF Restart (CVE-2026-73436)On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an adjacent OSPF neighbor may cause OSPF to restart unexpectedly. |
|
| CVE-2026-19640 | Sep 16, 2026 |
Arista EOS gNMI Authorization Bypass Allowing Privilege EscalationOn affected platforms running Arista EOS, an authenticated user with access to the gNMI (gRPC Network Management Interface) may receive incorrect authorization results, potentially allowing access beyond their currently assigned permissions. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks. |
|
| CVE-2026-73450 | Sep 16, 2026 |
Arista EOS MLAG Dual Primary State ErrDisable via Unauth Packets (v4.334.36)On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual Primary Detection network segment can send specially crafted packets to interfere with the dual-primary state. If the MLAG primary switch fails while these packets are present, the secondary switch incorrectly concludes it is in a dual-primary condition and err-disables its interfaces, leading to a traffic interruption. |
|
| CVE-2026-73460 | Sep 15, 2026 |
Premature IS-IS Graceful Restart Termination in Arista EOS <4.36.1FOn affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart procedure to terminate prematurely. This may result in traffic loss following a restart event. |
|
| CVE-2026-73459 | Sep 15, 2026 |
Arista EOS 4.36.0-4.36.1F IS-IS LSP PDU Injection Causes LSP PurgeOn affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate LSP to be unexpectedly purged from the IS-IS link-state database. This may result in traffic loss. |
|
| CVE-2026-73446 | Sep 15, 2026 |
Arista EOS 4.31-4.36: IS-IS Adjacency Tear-Down via Crafted Hello PDUOn affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacency. This may result in traffic disruption and loss of IP reachability for prefixes advertised through that adjacency. |
|
| CVE-2026-73444 | Sep 15, 2026 |
Arista EOS VRRPv2 IP-AH Auth Bypass Enables Master Role TakeoverOn affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment on which VRRP is running could bypass VRRP authentication and claim the virtual router master role, enabling the attacker to intercept, modify, or discard traffic that hosts on the segment send to the virtual gateway address. |
|
| CVE-2026-75945 | Sep 14, 2026 |
EOS 4.x Race Condition Leaves Supplicant Authorized After Clear Dot1X Host-AllA race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued. |
|
| CVE-2026-75944 | Sep 14, 2026 |
Race Cond. in EOS 4.36.x ACL Agent Leaves Stale Entry (CVE-2026-75944)A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants, resulting in incorrect access control enforcement. User interaction (an AclAgent restart by an administrator) is required for the unintended behavior to take effect. |
|
| CVE-2026-75943 | Sep 14, 2026 |
Arista EOS Traffic Leakage on Supplicant Removal (4.36.0)A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass without ACL enforcement. |
|
| CVE-2026-77191 | Sep 14, 2026 |
Arista EOS 4.35.0 ACL Bypass via Authenticated Supplicant WindowAn authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between the completion of the authentication phase and the full enforcement of its assigned ACL. |
|
| CVE-2026-73449 | Sep 14, 2026 |
Arista EOS 4.34-4.36 RADIUS Proxy Dynamic Auth BypassOn affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADIUS proxy client can prevent RADIUS dynamic authorization messages, including Change-of-Authorization (CoA) and Disconnect-Requests as defined in RFC 5176, from being applied to locally authenticated 802.1X sessions. This allows an endpoint session that a RADIUS server or network access control system has ordered disconnected to remain authorized on the network. Both 802.1X port authentication with dynamic authorization and RADIUS proxy with dynamic authorization must be explicitly configured for a deployment to be exposed to this issue. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks. |
|
| CVE-2026-7473 | Jun 05, 2026 |
Arista EOS <4.36: VXLAN/GRE Decap Misidentification Leads to Tunnel SpoofingOn affected platforms running Arista EOS where a tunnel decapsulation configurationsuch as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interfaceis present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild. |
|
| CVE-2025-8873 | Jun 04, 2026 |
Arista EOS IPsec DP DoS 4.33.x and 4.32.x seriesOn affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to stop processing all IPsec traffic. The control plane may detect this condition, and attempt to reset the IPsec processing pipeline. After reset traffic may not resume being processed. There is no impact to non-IPsec traffic or to IPsec traffic not originating or terminating on the system. This issue was reported by an Arista customer. |
|
| CVE-2023-5502 | Jun 04, 2026 |
EOS 4.254.31 Auth Bypass via 802.1x on Access VLANsOn affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, and routing enabled on the access VLAN of the ports, a malicious supplicant may be able to bypass the requirement to perform 802.1x authentication. |
|
| CVE-2024-27891 | Jun 04, 2026 |
Arista EOS <=4.32: ACL MACsec Egress BypassOn affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies may not be enforced for packets egressing on those ports. This can cause outgoing packets to incorrectly be allowed or denied. |
|
| CVE-2024-6858 | Jun 04, 2026 |
Arista EOS 4.284.31: Unauth Host via EAPOL in 802.1X ModeIn Aristas EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there exists an EAPOL capable device in the fallback VLAN. |
|
| CVE-2025-7048 | Jan 06, 2026 |
Arista EOS MACsec Crash via Crafted Packet (4.34.3.1M)On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption of dataplane traffic. |
|
| CVE-2025-8872 | Dec 16, 2025 |
Arista EOS OSPFv3 CPU Exhaustion via Crafted PacketOn affected platforms running Arista EOS with OSPFv3 configured, a specially crafted packet can cause the OSFPv3 process to have high CPU utilization which may result in the OSFPv3 process being restarted. This may cause disruption in the OSFPv3 routes on the switch. This issue was discovered internally by Arista and is not aware of any malicious uses of this issue in customer networks. |
|
| CVE-2025-2796 | May 27, 2025 |
Arista EOS IPsec Anti-Replay Duplicate Packet Forgery VulnerabilityOn affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection configured, EOS may exhibit unexpected behavior in specific cases. Received duplicate encrypted packets, which should be dropped under normal anti-replay protection, will instead be forwarded due to this vulnerability. Note: this issue does not affect VXLANSec or MACSec encryption functionality. |
|
| CVE-2024-9448 | May 08, 2025 |
Arista EOS Traffic Policy Skip Untagged Packets – Improper DropOn affected platforms running Arista EOS with Traffic Policies configured the vulnerability will cause received untagged packets not to hit Traffic Policy rules that they are expected to hit. If the rule was to drop the packet, the packet will not be dropped and instead will be forwarded as if the rule was not in place. This could lead to packets being delivered to unexpected destinations. |
|
| CVE-2024-11186 | May 08, 2025 |
Arista CV Portal Improper Access Control: Auth EscalationOn affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-premise. It does not impact CloudVision as-a-Service. |
|
| CVE-2024-12378 | May 08, 2025 |
Arista EOS Tunnelsec Agent Restart Exposes Packets in Clear over Secure VxLANOn affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear. |
|
| CVE-2025-0936 | May 07, 2025 |
Arista EOS gNOI RPC Exposes Remote Credentials via LoggingOn affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause these remote-server credentials to be logged or accounted on the local EOS device or possibly on other remote accounting servers (i.e. TACACS, RADIUS, etc). |
|
| CVE-2025-2767 | Apr 23, 2025 |
Arista NG Firewall XSS RCE via User-Agent HeaderArista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Minimal user interaction is required to exploit this vulnerability. The specific flaw exists within the processing of the User-Agent HTTP header. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-24407. |
|
| CVE-2025-1259 | Mar 04, 2025 |
Arista EOS gNOI Request Bypass via OpenConfigOn affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in users retrieving data that should not have been available |
|
| CVE-2025-1260 | Mar 04, 2025 |
Arista EOS gNOI bypass allows unauthorized config changesOn affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in unexpected configuration/operations being applied to the switch. |
|
| CVE-2024-5872 | Jan 10, 2025 |
Arista EOS VLAN Tag Misprocessing Causing Control Plane InstabilityOn affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, which may cause incorrect control plane behavior related to the packet, such as route flaps, multicast routes learnt, etc. |
|
| CVE-2024-7095 | Jan 10, 2025 |
Arista EOS SNMP snmpd Mem Leak by Crafted PacketOn affected platforms running Arista EOS with SNMP configured, if snmp-server transmit max-size is configured, under some circumstances a specially crafted packet can cause the snmpd process to leak memory. This may result in the snmpd process being terminated (causing SNMP requests to time out until snmpd is restarted) and memory pressure for other processes on the switch. Increased memory pressure can cause processes other than snmpd to be at risk for unexpected termination as well. |
|
| CVE-2024-6437 | Jan 10, 2025 |
Arista EOS PBR/BGP Flowspec IP Options BypassOn affected platforms running Arista EOS with one of the following features configured to redirect IP traffic to a next hop: policy-based routing (PBR), BGP Flowspec, or interface traffic policy -- certain IP traffic such as IPv4 packets with IP options may bypass the feature's set nexthop action and be slow-path forwarded (FIB routed) by the kernel as the packets are trapped to the CPU instead of following the redirect action's destination. |
|
| CVE-2024-12829 | Dec 20, 2024 |
Arista NG Firewall ExecManagerImpl Command Injection RCEArista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Authentication is required to exploit this vulnerability. The specific flaw exists within the ExecManagerImpl class. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-24015. |
|
| CVE-2024-12830 | Dec 20, 2024 |
Arista NG Firewall custom_handler Directory Traversal RCE VulnerabilityArista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the custom_handler method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the www-data user. Was ZDI-CAN-24019. |
|
| CVE-2024-12831 | Dec 20, 2024 |
Arista NG Firewall uvm_login Module Incorrect Authorization Privilege EscalationArista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Arista NG Firewall. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the uvm_login module. The issue results from incorrect authorization. An attacker can leverage this to escalate privileges to resources normally protected from the user. Was ZDI-CAN-24324. |
|
| CVE-2024-12832 | Dec 20, 2024 |
Arista NG Firewall SQL Injection Vulnerability in ReportEntry ClassArista NG Firewall ReportEntry SQL Injection Arbitrary File Read and Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files and disclose sensitive information on affected installations of Arista NG Firewall. Authentication is required to exploit this vulnerability. The specific flaw exists within the ReportEntry class. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the www-data user. Was ZDI-CAN-24325. |
|
| CVE-2023-24546 | Jun 13, 2023 |
Arista CloudVision Portal: Improper Access Control on Device ConnectionOn affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry and configuration data within the system than intended. This advisory impacts the Arista CloudVision Portal product when run on-premise. It does not impact CloudVision as-a-Service. |
|
| CVE-2023-24510 | Jun 05, 2023 |
Arista EOS DHCP Relay Agent Crash via Malformed DHCP PacketOn the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart. |
|
| CVE-2023-24512 | Apr 25, 2023 |
Arista EOS gNMI Streaming Agent Allows Arbitrary Config ChangeOn affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to update arbitrary configurations in the switch. This situation occurs only when the Streaming Telemetry Agent (referred to as the TerminAttr agent) is enabled and gNMI access is configured on the agent. Note: This gNMI over the Streaming Telemetry Agent scenario is mostly commonly used when streaming to a 3rd party system and is not used by default when streaming to CloudVision |
And others... |
| CVE-2023-24509 | Apr 13, 2023 |
Privilege Escalation in Arista EOS Standby Supervisor via RPR/SSOOn affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with RPR or SSO, an existing unprivileged user can login to the standby supervisor as a root user, leading to a privilege escalation. Valid user credentials are required in order to exploit this vulnerability. |
|
| CVE-2021-28510 | Jan 26, 2023 |
Arista EOS PTP Agent Crash DoS from Malformed PTP TLVFor certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invalid Type-Length-Value (TLV) causes the PTP agent to restart. Repeated restarts of the service will make the service unavailable. |
|